Log inSign up
Markus Vervier
8,291 posts
Markus Vervier profile banner
@marver

Markus Vervier

@marver
Security Vulnerability Coach, responsible for @x41sec and @persistent_psi Tweets here are my own.
Right here
persistent-security.net
Joined January 2009
604
Following
3,375
Followers
RepliesRepliesRepostsRepostsMediaMediaArticlesArticles

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @marver
    Markus Vervier
    @marver
    May 1
    Reality check your defenses! POC collection of the Month-of-Bypasses:
    GitHub - persistent-security/month-of-bypasses: Proof-of-Concepts for Detection Engineering...
    From github.com
  • @marver
    Markus Vervier
    @marver
    18h
    People were always asking why I think SGX isn’t the right tech for keeping contacts safe, here‘s why!
    @v12sec
    V12
    @v12sec
    Aug 26
    Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud. V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything. Two separate critical bugs: arbitrary read and RCE. Here's how. 🧵
    00:00
  • @marver
    Markus Vervier
    @marver
    Aug 22
    Pandemic for robots?
    @olivier_boschko
    Boschko
    @olivier_boschko
    Aug 20
    Now that Unitree has IPO'd, I'll drop what will likely be my last blog sometime next week. I'm not quite done writing just yet 🙃 It's ~3 months (~200h) of research condensed into ~70 minutes. Exploit is wormable, so if one G1 gets popped, it RCEs all other G1s in proximity
  • @marver
    Markus Vervier
    @marver
    Aug 19
    Looking forward to this one in person in NYC!
    @Persistent_Psi
    Nemesis | Adversarial Exposure Validation
    @Persistent_Psi
    Aug 18
    “You won’t believe how I used AI for pentesting”—this mixed with cocktails in a #NYC #securityspeakeasy? Jackpot. We are taking over for an unfiltered panel and open Q&A, bringing together a room full of sharp security leaders for conversations that usually happen off the record
  • @marver
    Markus Vervier
    @marver
    Aug 1
    What Huggingface and Anthropic call misalignment, I call feature: How to make AI agents go out of scope, leak their secrets and hack themselves (or other things)…This research was quite fun! Thx to #WeAreTroopers for having me!
    @Persistent_Psi
    Nemesis | Adversarial Exposure Validation
    @Persistent_Psi
    Jul 31
    Throwback to #TroopersConference where @marver showed us what happens when you run #AIpentesting in “YOLO mode.” The flaw? Agents trust data from targets they inspect. A single fake file or link turns an AI scanner into an automated credential leaker. 👉youtu.be/tP6n42NJ9KE?si…